🔐 CVE Alert

CVE-2026-9058

UNKNOWN 0.0

Improper Certificate Verification in Szafir SDK

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
11th

Szafir SDK returns a success status code from the cryptographic digital signature verification process (i.e. /VerifyingTaskItem/Signature/VerificationResult/Result/@code == 0, "Positively verified") even when the trust status of the signer's certificate could not be established (i.e. /VerifyingTaskItem/Signature/VerificationResult/SigningCertificate/@certificateType == "nondetermined"). This causes consuming applications to incorrectly treat the signature as valid despite an unverified certificate chain, enabling authentication bypass and user impersonation. This issue was fixed in version 463.

CWE CWE-637 CWE-393
Vendor krajowa izba rozliczeniowa
Product szafir sdk
Published May 25, 2026
Last Updated May 26, 2026
Stay Ahead of the Next One

Get instant alerts for krajowa izba rozliczeniowa szafir sdk

Be the first to know when new unknown vulnerabilities affecting krajowa izba rozliczeniowa szafir sdk are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Krajowa Izba Rozliczeniowa / Szafir SDK
0 < 463

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/05/CVE-2026-9058 elektronicznypodpis.pl: https://www.elektronicznypodpis.pl/

Credits

Michał Leszczyński (icedev.pl)